thedixitjain
- 10k skills
- 0 followers
- 2 repo stars
- 2 weeks ago last updated
- ▌ Exploiting Active Directory With Bloodhound · thedixitjain bundleBloodHound is a graph-based Active Directory reconnaissance tool that uses graph theory to reveal hidden and unintended relationships within AD environments. Red teams use BloodHound to identify attac
- ▌ Hardening Linux Endpoint With Cis Benchmark · thedixitjain bundle'Hardens Linux endpoints using CIS Benchmark recommendations for Ubuntu, RHEL, and CentOS to reduce attack surface, enforce security baselines, and meet compliance requirements. Use when deploying new Linux servers, remediating audit findings, or establishing security baselines for Linux infrastructure. Activates for requests involving Linux hardening, CIS benchmarks for Linux, server security baselines, or Linux configuration compliance. '
- ▌ Implementing Anti Phishing Training Program · thedixitjain bundleSecurity awareness training is the human layer of phishing defense. An effective anti-phishing training program combines regular simulations, interactive learning modules, metric tracking, and positiv
- ▌ Implementing Cisa Zero Trust Maturity Model · thedixitjain bundleImplement the CISA Zero Trust Maturity Model v2.0 across the five pillars of identity, devices, networks, applications, and data to achieve progressive organizational zero trust maturity.
- ▌ Implementing Disk Encryption With Bitlocker · thedixitjain bundle'Implements full disk encryption using Microsoft BitLocker on Windows endpoints to protect data at rest from unauthorized access in case of device loss or theft. Use when deploying encryption for compliance requirements, securing mobile workstations, or implementing data protection controls across the enterprise. Activates for requests involving BitLocker encryption, disk encryption, TPM configuration, or data-at-rest protection. '
- ▌ Implementing Hipaa Security Rule Safeguards · thedixitjain bundle>- Implement the HIPAA Security Rule (45 CFR Part 164 Subpart C) to protect electronic protected health information (ePHI): conduct the required risk analysis, deploy the administrative, physical, and technical safeguards, handle required vs addressable implementation specifications, execute Business Associate Agreements, and stand up breach-notification readiness. Use when an organization is a HIPAA covered entity or business associate, when protecting ePHI, when preparing for an OCR audit or responding to a breach, when performing a HIPAA Security Risk Analysis, when drafting or reviewing a BAA, or when mapping security controls to the §164.308/310/312/314/316 safeguards. Notes the 2025 NPRM proposed changes (not yet final). Keywords: HIPAA, HIPAA Security Rule, ePHI, PHI, 45 CFR 164, risk analysis, administrative safeguards, physical safeguards, technical safeguards, addressable,...
- ▌ Implementing Runtime Security With Tetragon · thedixitjain bundleImplement eBPF-based runtime security observability and enforcement in Kubernetes clusters using Cilium Tetragon for kernel-level threat detection and policy enforcement.
- ▌ Implementing Siem Correlation Rules For Apt · thedixitjain bundleWrite multi-event correlation rules that detect APT lateral movement by chaining Windows authentication events, process execution telemetry, and network connection logs across hosts. Uses Splunk SPL and Sigma rule format to correlate Event IDs 4624, 4648, 4688, and Sysmon Events 1/3 within sliding time windows to surface attack sequences invisible to single-event detections.
- ▌ Implementing Ticketing System For Incidents · thedixitjain bundle'Implements an integrated incident ticketing system connecting SIEM alerts to ServiceNow, Jira, or TheHive for structured incident tracking, SLA management, escalation workflows, and compliance documentation. Use when SOC teams need formalized incident lifecycle management with automated ticket creation, assignment routing, and resolution tracking. '
- ▌ Integrating Dast With Owasp Zap In Pipeline · thedixitjain bundle'This skill covers integrating OWASP ZAP (Zed Attack Proxy) for Dynamic Application Security Testing in CI/CD pipelines. It addresses configuring baseline, full, and API scans against running applications, interpreting ZAP findings, tuning scan policies, and establishing DAST quality gates in GitHub Actions and GitLab CI. '
- ▌ Performing Agentless Vulnerability Scanning · thedixitjain bundleConfigure and execute agentless vulnerability scanning using network protocols, cloud snapshot analysis, and API-based discovery to assess systems without installing endpoint agents.
- ▌ Performing Authenticated Vulnerability Scan · thedixitjain bundleAuthenticated (credentialed) vulnerability scanning uses valid system credentials to log into target hosts and perform deep inspection of installed software, patches, configurations, and security sett
- ▌ Performing Endpoint Forensics Investigation · thedixitjain bundle'Performs digital forensics investigation on compromised endpoints including memory acquisition, disk imaging, artifact analysis, and timeline reconstruction. Use when investigating security incidents, collecting evidence for legal proceedings, or analyzing endpoint compromise scope. Activates for requests involving endpoint forensics, memory analysis, disk forensics, or incident investigation. '
- ▌ Performing False Positive Reduction In Siem · thedixitjain bundlePerform systematic SIEM false positive reduction through rule tuning, threshold adjustment, correlation refinement, and threat intelligence enrichment to combat alert fatigue.
- ▌ Performing Firmware Extraction With Binwalk · thedixitjain bundle'Performs firmware image extraction and analysis using binwalk to identify embedded filesystems, compressed archives, bootloaders, kernel images, and cryptographic material. Covers entropy analysis for detecting encrypted or compressed regions, recursive extraction of nested archives, SquashFS/CramFS/JFFS2 filesystem mounting, and string analysis for credential and configuration discovery. Activates for requests involving firmware reverse engineering, IoT device analysis, embedded system security assessment, or router/camera firmware extraction. '
- ▌ Performing Network Forensics With Wireshark · thedixitjain bundleCapture and analyze network traffic using Wireshark and tshark to reconstruct network events, extract artifacts, and identify malicious communications.
- ▌ Performing Oil Gas Cybersecurity Assessment · thedixitjain bundle'This skill covers conducting cybersecurity assessments specific to oil and gas facilities including upstream (exploration/production), midstream (pipeline/transport), and downstream (refining/distribution) operations. It addresses SCADA systems controlling pipeline operations, DCS for refinery process control, safety instrumented systems for hazardous processes, remote terminal units at unmanned wellhead sites, and compliance with API 1164, TSA Pipeline Security Directives, IEC 62443, and NIST Cybersecurity Framework for critical infrastructure. '
- ▌ Performing Ot Vulnerability Scanning Safely · thedixitjain bundle'Perform vulnerability scanning in OT/ICS environments safely using passive monitoring, native protocol queries, and carefully controlled active scanning with Tenable OT Security to identify vulnerabilities without disrupting industrial processes or crashing legacy controllers. '
- ▌ Performing Phishing Simulation With Gophish · thedixitjain bundleGoPhish is an open-source phishing simulation framework used by security teams to conduct authorized phishing awareness campaigns. It provides campaign management, email template creation, landing pag
- ▌ Performing Ssl Tls Inspection Configuration · thedixitjain bundleConfigure SSL/TLS inspection on network security devices to decrypt, inspect, and re-encrypt HTTPS traffic for threat detection while managing certificates, exemptions, and privacy compliance.
- ▌ Performing Threat Hunting With Elastic Siem · thedixitjain bundle'Performs proactive threat hunting in Elastic Security SIEM using KQL/EQL queries, detection rules, and Timeline investigation to identify threats that evade automated detection. Use when SOC teams need to hunt for specific ATT&CK techniques, investigate anomalous behaviors, or validate detection coverage gaps using Elasticsearch and Kibana Security. '
- ▌ Performing Web Application Penetration Test · thedixitjain bundle'Performs systematic security testing of web applications following the OWASP Web Security Testing Guide (WSTG) methodology to identify vulnerabilities in authentication, authorization, input validation, session management, and business logic. The tester uses Burp Suite as the primary interception proxy alongside manual testing techniques to find flaws that automated scanners miss. Activates for requests involving web app pentest, OWASP testing, application security assessment, or web vulnerability testing. '
- ▌ Triaging Security Incident With Ir Playbook · thedixitjain bundleClassify and prioritize security incidents using structured IR playbooks to determine severity, assign response teams, and initiate appropriate response procedures.
- ▌ Performing Thick Client Application Penetration Test · thedixitjain bundleConduct a thick client application penetration test to identify insecure local storage, hardcoded credentials, DLL hijacking, memory manipulation, and insecure API communication in desktop applications using dnSpy, Procmon, and Burp Suite.
- ▌ Implementing API Abuse Detection With Rate Limiting · thedixitjain bundleImplement API abuse detection using token bucket, sliding window, and adaptive rate limiting algorithms to prevent DDoS, brute force, and credential stuffing attacks.
- ▌ Implementing Cloud Vulnerability Posture Management · thedixitjain bundleImplement Cloud Security Posture Management using AWS Security Hub, Azure Defender for Cloud, and open-source tools like Prowler and ScoutSuite for multi-cloud vulnerability detection.
- ▌ Implementing Container Network Policies With Calico · thedixitjain bundleEnforce Kubernetes network segmentation using Calico CNI network policies and global network policies to control pod-to-pod traffic, restrict egress, and implement zero-trust microsegmentation.
- ▌ Performing AWS Account Enumeration With Scout Suite · thedixitjain bundlePerform comprehensive security posture assessment of AWS accounts using ScoutSuite to enumerate resources, identify misconfigurations, and generate actionable security reports.
- ▌ Performing Kubernetes Cis Benchmark With Kube Bench · thedixitjain bundleAudit Kubernetes cluster security posture against CIS benchmarks using kube-bench with automated checks for control plane, worker nodes, and RBAC.
- ▌ Analyzing Slack Space And File System Artifacts · thedixitjain bundleExamine file system slack space, MFT entries, USN journal, and alternate data streams to recover hidden data and reconstruct file activity on NTFS volumes.
- ▌ Implementing Google Workspace Sso Configuration · thedixitjain bundleConfigure SAML 2.0 single sign-on for Google Workspace with a third-party identity provider, enabling centralized authentication and enforcing organization-wide access policies.
- ▌ Performing Mobile App Certificate Pinning Bypass · thedixitjain bundle'Bypasses SSL/TLS certificate pinning implementations in Android and iOS applications to enable traffic interception during authorized security assessments. Covers OkHttp, TrustManager, NSURLSession, and third-party pinning library bypass techniques using Frida, Objection, and custom scripts. Activates for requests involving certificate pinning bypass, SSL pinning defeat, mobile TLS interception, or proxy-resistant app testing. '
- ▌ Acm Ieee Joint Conference On Digital Libraries · thedixitjainUse when targeting ACM/IEEE Joint Conference on Digital Libraries (JCDL) or deciding whether a computer-science manuscript fits this venue. Encodes conference fit, framing, evidence bar, submission-cycle checks, rebuttal posture, and desk-reject risks for digital libraries.
- ▌ Communications On Pure And Applied Mathematics · thedixitjainUse when targeting Communications on Pure and Applied Mathematics (CPAM) or deciding whether an analysis, PDE, or applied-mathematics manuscript fits this Courant/Wiley venue. Encodes the journal's fit, framing, proof standard, house style, official-submission re-check, and desk-reject heuristics.
- ▌ Conbio Conservation Relevance And Implications · thedixitjainUse when sharpening the conservation significance and actionable implications of a Conservation Biology manuscript. The journal requires results to have direct, transferable implications for conserving biological diversity and to bridge science and practice. Frames the so-what and the recommendations; it does not overstate evidence or fabricate impact.
- ▌ European Conference On Artificial Intelligence · thedixitjainUse when targeting European Conference on Artificial Intelligence (ECAI) or deciding whether a computer-science manuscript fits this venue. Encodes conference fit, framing, evidence bar, submission-cycle checks, rebuttal posture, and desk-reject risks for AI/ML regional flagship.
- ▌ Journal Of The Mechanics And Physics Of Solids · thedixitjainUse when targeting the Journal of the Mechanics and Physics of Solids (JMPS) or deciding whether a fundamental solid-mechanics manuscript fits this venue. Encodes the journal's fit, the physical-insight-plus-mathematical-rigor bar, breadth across solid mechanics, the JMPS-vs-plasticity-journal routing, official-submission re-check, and desk-reject heuristics.
- ▌ The International Journal Of Robotics Research · thedixitjainUse when targeting The International Journal of Robotics Research (IJRR) or deciding whether a robotics manuscript fits this venue. Encodes the journal's fit, the longer-form conceptually-framed-and-general contribution bar, depth-and-generality rigor, the IJRR-vs-T-RO routing, house style, official-submission re-check, and desk-reject heuristics.
- ▌ Accessibility Compliance Accessibility Audit · thedixitjain bundleYou are an accessibility expert specializing in WCAG compliance, inclusive design, and assistive technology compatibility. Conduct audits, identify barriers, and provide remediation guidance.
- ▌ Analyzing Malware Sandbox Evasion Techniques · thedixitjain bundleDetect sandbox evasion techniques in malware samples by analyzing timing checks, VM artifact queries, user interaction detection, and sleep inflation patterns from Cuckoo/AnyRun behavioral reports
- ▌ Analyzing Network Covert Channels In Malware · thedixitjain bundleDetect and analyze covert communication channels used by malware including DNS tunneling, ICMP exfiltration, steganographic HTTP, and protocol abuse for C2 and data exfiltration.
- ▌ Configuring Microsegmentation For Zero Trust · thedixitjain bundleConfigure microsegmentation policies to enforce least-privilege workload-to-workload access using tools like VMware NSX, Illumio, and Calico, preventing lateral movement in zero trust architectures.
- ▌ Detecting Typosquatting Packages In NPM Pypi · thedixitjain bundle'Detects typosquatting attacks in npm and PyPI package registries by analyzing package name similarity using Levenshtein distance and other string metrics, examining publish date heuristics to identify recently created packages mimicking established ones, and flagging download count anomalies where suspicious packages have disproportionately low usage compared to their legitimate targets. The analyst queries the PyPI JSON API and npm registry API to gather package metadata for automated comparison. Activates for requests involving package typosquatting detection, dependency confusion analysis, malicious package identification, or software supply chain threat hunting in package registries. '
- ▌ Executing Active Directory Attack Simulation · thedixitjain bundle'Executes authorized attack simulations against Active Directory environments to identify misconfigurations, weak credentials, dangerous privilege paths, and exploitable trust relationships that could lead to domain compromise. The tester uses BloodHound for attack path analysis, Mimikatz for credential extraction, and Impacket for protocol-level attacks including Kerberoasting, AS-REP Roasting, and delegation abuse. Activates for requests involving Active Directory pentest, AD attack simulation, domain compromise testing, or Kerberos attack assessment. '
- ▌ Hunting For Defense Evasion Via Timestomping · thedixitjain bundle'Detect NTFS timestamp manipulation (MITRE T1070.006) by comparing $STANDARD_INFORMATION vs $FILE_NAME timestamps in the MFT. Uses analyzeMFT and Python to identify files with anomalous temporal patterns indicating anti-forensic timestomping activity. '
- ▌ Implementing Aes Encryption For Data At REST · thedixitjain bundleAES (Advanced Encryption Standard) is a symmetric block cipher standardized by NIST (FIPS 197) used to protect classified and sensitive data. This skill covers implementing AES-256 encryption in GCM m
- ▌ Implementing AWS Config Rules For Compliance · thedixitjain bundle'Implementing AWS Config rules for continuous compliance monitoring of AWS resources, deploying managed and custom rules aligned to CIS and PCI DSS frameworks, configuring automatic remediation with SSM Automation, and aggregating compliance data across accounts. '
- ▌ Implementing Google Workspace Admin Security · thedixitjain bundle'Implements comprehensive Google Workspace security hardening including admin console configuration, phishing-resistant MFA enforcement, DLP policies, email authentication (SPF/DKIM/DMARC), OAuth app control, and external sharing restrictions. Activates for requests involving Google Workspace hardening, G Suite security configuration, or cloud office security administration. '
- ▌ Implementing Hashicorp Vault Dynamic Secrets · thedixitjain bundle'Implements HashiCorp Vault dynamic secrets engines for database credentials, AWS IAM keys, and PKI certificates with automatic generation, lease management, and credential rotation to eliminate static secrets in application configurations. Activates for requests involving Vault secrets engine configuration, dynamic database credentials, ephemeral cloud credentials, or automated secret rotation. '
- ▌ Performing API Security Testing With Postman · thedixitjain bundle'Uses Postman to perform structured API security testing by building collections that test for OWASP API Security Top 10 vulnerabilities including authentication bypass, authorization flaws, injection, and data exposure. The tester creates environments with multiple user roles, writes test scripts for automated security validation, and integrates Postman with OWASP ZAP and Newman for CI/CD security testing. Activates for requests involving Postman security testing, API security collection, automated API testing, or OWASP API testing with Postman. '
- ▌ Performing Dns Enumeration And Zone Transfer · thedixitjain bundle'Enumerates DNS records, attempts zone transfers, brute-forces subdomains, and maps DNS infrastructure during authorized reconnaissance to identify attack surface, misconfigurations, and information disclosure in target domains. '
- ▌ Performing Malware Persistence Investigation · thedixitjain bundleSystematically investigate all persistence mechanisms on Windows and Linux systems to identify how malware survives reboots and maintains access.
- ▌ Performing S7comm Protocol Security Analysis · thedixitjain bundle'Perform security analysis of Siemens S7comm and S7CommPlus protocols used by SIMATIC S7 PLCs to identify vulnerabilities including replay attacks, integrity bypass, unauthorized CPU stop commands, and program download manipulation exploiting weaknesses in S7-300, S7-400, S7-1200, and S7-1500 controllers. '
- ▌ Performing Soap Web Service Security Testing · thedixitjain bundlePerform security testing of SOAP web services by analyzing WSDL definitions and testing for XML injection, XXE, WS-Security bypass, and SOAPAction spoofing.
- ▌ Triaging Vulnerabilities With Ssvc Framework · thedixitjain bundleTriage and prioritize vulnerabilities using CISA's Stakeholder-Specific Vulnerability Categorization (SSVC) decision tree framework to produce actionable remediation priorities.
- ▌ Scaffolding Oracle To Postgres Migration Test Project · thedixitjainScaffolds an xUnit integration test project for validating Oracle-to-PostgreSQL database migration behavior in .NET solutions. Creates the test project, transaction-rollback base class, and seed data manager. Use when setting up test infrastructure before writing migration integration tests, or when a test project is needed for Oracle-to-PostgreSQL validation.
- ▌ Detecting Anomalies In Industrial Control Systems · thedixitjain bundle'This skill covers deploying anomaly detection systems for industrial control environments using machine learning models trained on OT network baselines, physics-based process models, and behavioral analysis of industrial protocol communications. It addresses building normal behavior profiles for SCADA polling patterns, detecting deviations in Modbus/DNP3/OPC UA traffic, identifying rogue devices, and correlating network anomalies with physical process data from historians. '
- ▌ Implementing Azure Ad Privileged Identity Management · thedixitjain bundleConfigure Microsoft Entra Privileged Identity Management to enforce just-in-time role activation, approval workflows, and access reviews for Azure AD privileged roles.
- ▌ Quality Documentation Manager · thedixitjain bundleDocument control system management for medical device QMS. Covers document numbering, version control, change management, and 21 CFR Part 11 compliance. Use when working on document control procedures, change control workflows, document numbering, version management, electronic signature compliance, or regulatory documentation review.
- ▌ Create Github Issues Feature From Implementation Plan · thedixitjainCreate GitHub Issues from implementation plan phases using feature_request.yml or chore_request.yml templates.
- ▌ Performing Android App Static Analysis With Mobsf · thedixitjain bundle'Performs automated static analysis of Android applications using Mobile Security Framework (MobSF) to identify hardcoded secrets, insecure permissions, vulnerable components, weak cryptography, and code-level security flaws without executing the application. Use when assessing Android APK/AAB files for security vulnerabilities before deployment, during penetration testing, or as part of CI/CD security gates. Activates for requests involving Android static analysis, MobSF scanning, APK security assessment, or mobile application code review. '
- ▌ Ieee International Requirements Engineering Conference · thedixitjainUse when targeting IEEE International Requirements Engineering Conference (RE) or deciding whether a computer-science manuscript fits this venue. Encodes conference fit, framing, evidence bar, submission-cycle checks, rebuttal posture, and desk-reject risks for requirements engineering.
- ▌ Acm Ieee Symposium On Logic In Computer Science · thedixitjainUse when targeting ACM/IEEE Symposium on Logic in Computer Science (LICS) or deciding whether a computer-science manuscript fits this venue. Encodes conference fit, framing, evidence bar, submission-cycle checks, rebuttal posture, and desk-reject risks for logic in CS.
- ▌ Bulletin Of The American Meteorological Society · thedixitjainUse when targeting the Bulletin of the American Meteorological Society (BAMS) or deciding whether a broad-interest atmospheric/oceanic/hydrologic-sciences contribution fits this venue. Encodes the journal's review-and-community positioning, the broad-audience-significance bar, synthesis and field-campaign expectations, AMS house style, official-submission re-check, and misfit heuristics.
- ▌ International Conference On Pattern Recognition · thedixitjainUse when targeting International Conference on Pattern Recognition (ICPR) or deciding whether a computer-science manuscript fits this venue. Encodes conference fit, framing, evidence bar, submission-cycle checks, rebuttal posture, and desk-reject risks for pattern recognition.
- ▌ Journal Of Quantitative Technological Economics · thedixitjainUse when targeting 《数量经济技术经济研究》(The Journal of Quantitative & Technological Economics, JQTE) — the CASS journal for quantitative economics, econometric methods, technical economics, input-output, macro-econometric forecasting, and technology/innovation evaluation. Apply when the contribution is method-application or measurement (productivity, efficiency, forecasting) rather than a pure causal-policy narrative.
- ▌ Manufacturing And Service Operations Management · thedixitjainUse when targeting Manufacturing and Service Operations Management (M&SOM) or deciding whether an operations-management theory / modeling / empirical manuscript fits this venue. Encodes the journal's fit, framing, method-and-evidence bar, house style, official-submission re-check, and desk-reject heuristics.
- ▌ Analyzing Office365 Audit Logs For Compromise · thedixitjain bundleParse Office 365 Unified Audit Logs via Microsoft Graph API to detect email forwarding rule creation, inbox delegation, suspicious OAuth app grants, and other indicators of account compromise.
- ▌ Analyzing Threat Actor Ttps With Mitre Attack · thedixitjain bundleMITRE ATT&CK is a globally-accessible knowledge base of adversary tactics, techniques, and procedures (TTPs) based on real-world observations. This skill covers systematically mapping threat actor beh
- ▌ Analyzing Typosquatting Domains With Dnstwist · thedixitjain bundleDetect typosquatting, homograph phishing, and brand impersonation domains using dnstwist to generate domain permutations and identify registered lookalike domains targeting your organization.
- ▌ Building Threat Intelligence Feed Integration · thedixitjain bundle'Builds automated threat intelligence feed integration pipelines connecting STIX/TAXII feeds, open-source threat intel, and commercial TI platforms into SIEM and security tools for real-time IOC matching and alerting. Use when SOC teams need to operationalize threat intelligence by automating feed ingestion, normalization, scoring, and distribution to detection systems. '
- ▌ Building Vulnerability Aging And Sla Tracking · thedixitjain bundleImplement a vulnerability aging dashboard and SLA tracking system to measure remediation performance against severity-based timelines and drive accountability.
- ▌ Bypassing Authentication With Forced Browsing · thedixitjain bundleDiscovering and accessing unprotected pages, APIs, and administrative interfaces by enumerating URLs and bypassing authentication controls during authorized security assessments.
- ▌ Conducting External Reconnaissance With Osint · thedixitjain bundle'Conducts external reconnaissance using Open Source Intelligence (OSINT) techniques to map an organization''s external attack surface without directly interacting with target systems. The tester gathers information from public sources including DNS records, certificate transparency logs, search engines, social media, code repositories, and data breach databases to build a comprehensive target profile. Activates for requests involving OSINT reconnaissance, external footprinting, attack surface mapping, or passive information gathering. '
- ▌ Configuring Snort Ids For Intrusion Detection · thedixitjain bundle'Installs, configures, and tunes Snort 3 intrusion detection system to monitor network traffic for malicious activity using custom and community rulesets, preprocessors, and alert output plugins on authorized network segments. '
- ▌ Detecting Evasion Techniques In Endpoint Logs · thedixitjain bundle'Detects defense evasion techniques used by adversaries in endpoint logs including log tampering, timestomping, process injection, and security tool disabling. Use when investigating suspicious endpoint behavior, building detection rules for evasion tactics, or conducting threat hunting for stealthy adversary activity. Activates for requests involving evasion detection, defense evasion analysis, log tampering detection, or MITRE ATT&CK TA0005. '
- ▌ Exploiting Ms17 010 Eternalblue Vulnerability · thedixitjain bundleMS17-010 (EternalBlue) is a critical vulnerability in Microsoft's SMBv1 implementation that allows remote code execution. Originally discovered by the NSA and leaked by the Shadow Brokers in 2017, it
- ▌ Detecting Lateral Movement In Network · thedixitjain bundle'Identifies lateral movement techniques in enterprise networks by analyzing authentication logs, network flows, SMB traffic, and RDP sessions using Zeek, Velociraptor, and SIEM correlation rules to detect attackers moving between systems. '
- ▌ Detecting Port Scanning With Fail2ban · thedixitjain bundle'Configures Fail2ban with custom filters and actions to detect port scanning activity, SSH brute force attempts, and network reconnaissance, automatically banning offending IP addresses and alerting security teams to suspicious network probing. '
- ▌ Exploiting Nopac Cve 2021 42278 42287 · thedixitjain bundleExploit the noPac vulnerability chain (CVE-2021-42278 sAMAccountName spoofing and CVE-2021-42287 KDC PAC confusion) to escalate from standard domain user to Domain Admin in Active Directory environments.
- ▌ Implementing Ics Firewall With Tofino · thedixitjain bundle'Deploy and configure Tofino industrial firewalls from Belden/Hirschmann to protect SCADA systems and PLCs using deep packet inspection for OT protocols including Modbus, EtherNet/IP, OPC, and S7comm, enforcing granular access control between ICS security zones. '
- ▌ Implementing Iec 62443 Security Zones · thedixitjain bundle'This skill covers designing and implementing security zones and conduits for industrial automation and control systems (IACS) per IEC 62443-3-2. It addresses zone partitioning based on risk assessment, assigning Security Level targets (SL-T), designing conduit security controls, implementing microsegmentation with industrial firewalls, and validating zone architecture through traffic analysis and penetration testing against the Purdue Reference Model. '
- ▌ Investigating Phishing Email Incident · thedixitjain bundle'Investigates phishing email incidents from initial user report through header analysis, URL/attachment detonation, impacted user identification, and containment actions using SOC tools like Splunk, Microsoft Defender, and sandbox analysis platforms. Use when a reported phishing email requires full incident investigation to determine scope and impact. '
- ▌ Performing Hash Cracking With Hashcat · thedixitjain bundleHash cracking is an essential skill for penetration testers and security auditors to evaluate password strength. Hashcat is the world's fastest password recovery tool, supporting over 300 hash types w
- ▌ Performing Lateral Movement Detection · thedixitjain bundle'Detects lateral movement techniques including Pass-the-Hash, PsExec, WMI execution, RDP pivoting, and SMB-based spreading using SIEM correlation of Windows event logs, network flow data, and endpoint telemetry mapped to MITRE ATT&CK Lateral Movement (TA0008) techniques. '
- ▌ Conducting Man In The Middle Attack Simulation · thedixitjain bundle'Simulates man-in-the-middle attacks using Ettercap, mitmproxy, and Bettercap in authorized environments to intercept, analyze, and modify network traffic for testing encryption enforcement, certificate validation, and detection capabilities. '
- ▌ Conducting Social Engineering Penetration Test · thedixitjain bundleDesign and execute a social engineering penetration test including phishing, vishing, smishing, and physical pretexting campaigns to measure human security resilience and identify training gaps.
- ▌ Exploiting Smb Vulnerabilities With Metasploit · thedixitjain bundle'Identifies and exploits SMB protocol vulnerabilities using Metasploit Framework during authorized penetration tests to demonstrate risks from unpatched Windows systems, misconfigured shares, and weak authentication in enterprise networks. '
- ▌ Performing Cloud Penetration Testing With Pacu · thedixitjain bundle'Performing authorized AWS penetration testing using Pacu, the open-source AWS exploitation framework, to enumerate IAM configurations, discover privilege escalation paths, test credential harvesting, and validate security controls through systematic attack simulation. '
- ▌ Performing Web Application Scanning With Nikto · thedixitjain bundleNikto is an open-source web server and web application scanner that tests against over 7,000 potentially dangerous files/programs, checks for outdated versions of over 1,250 servers, and identifies ve
- ▌ Testing For Xss Vulnerabilities With Burpsuite · thedixitjain bundleIdentifying and validating cross-site scripting vulnerabilities using Burp Suite's scanner, intruder, and repeater tools during authorized security assessments.
- ▌ Agent Orchestration Multi Agent Optimize · thedixitjainOptimize multi-agent systems with coordinated profiling, workload distribution, and cost-aware orchestration. Use when improving agent performance, throughput, or reliability.
- ▌ Chief AI Officer Advisor · thedixitjain bundleChief AI Officer advisory for startups: model build-vs-buy decisions (API vs fine-tune vs in-house), AI risk classification under EU AI Act + US state patchwork, AI cost economics (API-to-self-hosted breakeven), and AI team org evolution. Use when deciding whether to call an API or fine-tune, classifying AI use cases for regulatory risk, calculating when self-hosting pays off, sequencing AI hires, or when user mentions CAIO, AI strategy, model selection, foundation model, fine-tuning, EU AI Act, NIST AI RMF, AI governance, model risk, or AI economics. Strategic only — does not duplicate engineering AI/ML skills.
- ▌ Exploiting Template Injection Vulnerabilities · thedixitjain bundleDetecting and exploiting Server-Side Template Injection (SSTI) vulnerabilities across Jinja2, Twig, Freemarker, and other template engines to achieve remote code execution.
- ▌ Implementing API Rate Limiting And Throttling · thedixitjain bundle'Implements API rate limiting and throttling controls using token bucket, sliding window, and fixed window algorithms to protect against brute force attacks, credential stuffing, resource exhaustion, and API abuse. The engineer configures per-user, per-IP, and per-endpoint rate limits using Redis-backed counters, API gateway plugins, or application middleware, and implements proper HTTP 429 responses with Retry-After headers. Activates for requests involving rate limiting implementation, API throttling setup, request quota management, or API abuse prevention. '
- ▌ Implementing Honeytokens For Breach Detection · thedixitjain bundle'Deploys canary tokens and honeytokens (fake AWS credentials, DNS canaries, document beacons, database records) that trigger alerts when accessed by attackers. Uses the Canarytokens API and custom webhook integrations for breach detection. Use when building deception-based early warning systems for intrusion detection. '
- ▌ Conference On Machine Learning And Systems · thedixitjainUse when targeting Conference on Machine Learning and Systems (MLSys) or deciding whether a computer-science manuscript fits this venue. Encodes conference fit, framing, evidence bar, submission-cycle checks, rebuttal posture, and desk-reject risks for ML systems.
- ▌ Auditing Azure Active Directory Configuration · thedixitjain bundle'Auditing Microsoft Entra ID (Azure Active Directory) configuration to identify risky authentication policies, overly permissive role assignments, stale accounts, conditional access gaps, and guest user risks using AzureAD PowerShell, Microsoft Graph API, and ScoutSuite. '
- ▌ Auditing Kubernetes Rbac Privilege Escalation · thedixitjain bundleFind over-permissive RBAC roles and service-account token abuse paths in Kubernetes using kubectl auth can-i, rbac-police, kubectl-who-can, and rakkess during authorized cluster security reviews.
- ▌ Building Ioc Enrichment Pipeline With Opencti · thedixitjain bundleOpenCTI is an open-source platform for managing cyber threat intelligence knowledge, built on STIX 2.1 as its native data model. This skill covers building an automated IOC enrichment pipeline using O